package session import ( "crypto/hmac" "crypto/sha256" "crypto/subtle" "encoding/base64" "net" "net/http" "strconv" "strings" "sync" "time" ) const ( CookieName = "mangabm_session" // 60 days: long enough that a phone stays logged in between reading spells. sessionTTL = 60 * 24 * time.Hour // Domain separation, so the session key can never collide with any other // use of the secrets it is derived from. Changing this string logs // everyone out. sessionKeyPurpose = "mangabm-web-session-v1" ) // Key derives the cookie-signing key from both secrets. Sessions are // stateless — there is no session table — so rotating either API_TOKEN or // WEB_PASSWORD invalidates every outstanding cookie at once. The \x00 // separator prevents the concatenation ambiguity a bare apiToken+webPassword // would have (e.g. "ab"+"c" colliding with "a"+"bc"). func Key(apiToken, webPassword string) []byte { sum := sha256.Sum256([]byte(apiToken + "\x00" + webPassword + sessionKeyPurpose)) return sum[:] } // Sign encodes ".". func Sign(key []byte, expiryMs int64) string { payload := strconv.FormatInt(expiryMs, 10) return payload + "." + sessionMAC(key, payload) } func sessionMAC(key []byte, payload string) string { mac := hmac.New(sha256.New, key) mac.Write([]byte(payload)) return base64.RawURLEncoding.EncodeToString(mac.Sum(nil)) } // Verify checks shape, then expiry, then the signature — in that order. // The signature comparison is constant-time; the checks before it only look at // data the holder already supplied, so their timing leaks nothing. func Verify(key []byte, value string, nowMs int64) bool { payload, sig, ok := strings.Cut(value, ".") if !ok { return false } expiry, err := strconv.ParseInt(payload, 10, 64) if err != nil || expiry <= nowMs { return false } want := sessionMAC(key, payload) return subtle.ConstantTimeCompare([]byte(sig), []byte(want)) == 1 } // isHTTPS reports whether the browser's connection is encrypted. Behind Traefik // the Go server itself speaks plain HTTP, so the forwarded header is the only // signal; without this check the Secure cookie would never be set in // production, and setting it unconditionally would break http://localhost dev. func isHTTPS(r *http.Request) bool { return r.TLS != nil || r.Header.Get("X-Forwarded-Proto") == "https" } func SetCookie(w http.ResponseWriter, r *http.Request, key []byte) { http.SetCookie(w, &http.Cookie{ Name: CookieName, Value: Sign(key, time.Now().Add(sessionTTL).UnixMilli()), Path: "/", MaxAge: int(sessionTTL / time.Second), HttpOnly: true, Secure: isHTTPS(r), SameSite: http.SameSiteLaxMode, }) } func ClearCookie(w http.ResponseWriter, r *http.Request) { http.SetCookie(w, &http.Cookie{ Name: CookieName, Value: "", Path: "/", MaxAge: -1, HttpOnly: true, Secure: isHTTPS(r), SameSite: http.SameSiteLaxMode, }) } const ( MaxFailures = 10 Window = 20 * time.Minute ) // ClientIP returns the address the reverse proxy actually observed. // // Traefik appends the peer address to whatever X-Forwarded-For the client sent, // so the leftmost entry is attacker-controlled and the rightmost is not. Go's // Header.Get would only read the first header line, which a client can preempt // by sending its own; Values covers every line so the true last hop is found. // RemoteAddr is useless behind the proxy — it is always the Traefik container — // so it serves only as the direct-connection fallback for local development. func ClientIP(r *http.Request) string { if vals := r.Header.Values("X-Forwarded-For"); len(vals) > 0 { hops := strings.Split(vals[len(vals)-1], ",") if ip := strings.TrimSpace(hops[len(hops)-1]); ip != "" { return ip } } host, _, err := net.SplitHostPort(r.RemoteAddr) if err != nil { return r.RemoteAddr } return host } // LoginLimiter throttles password guessing: MaxFailures failures inside a // rolling Window blocks further attempts from that IP until the oldest one // ages out. There is no permanent ban and no unlock step. // // Behind carrier-grade NAT this budget is shared with every other subscriber on // the same public address, so a stranger can lock the owner out for up to one // window. That is accepted: the block self-heals, and ten attempts is generous // for a mistyped password. // // State is in memory and per-process, so a restart clears it. Entries are // pruned lazily on access; for a single-user deployment the map cannot grow // past the handful of addresses that ever attempt a login. type LoginLimiter struct { mu sync.Mutex failures map[string][]time.Time } func NewLoginLimiter() *LoginLimiter { return &LoginLimiter{failures: make(map[string][]time.Time)} } // retryAfter returns how long ip must wait, or zero when it may try now. func (l *LoginLimiter) RetryAfter(ip string, now time.Time) time.Duration { l.mu.Lock() defer l.mu.Unlock() recent := l.pruneLocked(ip, now) if len(recent) < MaxFailures { return 0 } return recent[0].Add(Window).Sub(now) } func (l *LoginLimiter) Fail(ip string, now time.Time) { l.mu.Lock() defer l.mu.Unlock() l.failures[ip] = append(l.pruneLocked(ip, now), now) } func (l *LoginLimiter) Reset(ip string) { l.mu.Lock() defer l.mu.Unlock() delete(l.failures, ip) } // pruneLocked drops attempts older than the window and returns what is left. // The caller must hold l.mu. func (l *LoginLimiter) pruneLocked(ip string, now time.Time) []time.Time { cutoff := now.Add(-Window) // In-place filter: kept reuses the backing array of the slice being // ranged over. Safe to alias because append writes at index len(kept), // which is always <= the range index i, and element i is read before // that write — the write cursor can never overtake the read cursor. kept := l.failures[ip][:0] for _, at := range l.failures[ip] { if at.After(cutoff) { kept = append(kept, at) } } if len(kept) == 0 { delete(l.failures, ip) return nil } l.failures[ip] = kept return kept }